Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(storage): clear obsolete onboarding intent by mikemikimike · Pull Request #3571 · apache/maka · GitHub
Skip to content

fix(storage): clear obsolete onboarding intent - #3571

Merged
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent
Aug 23, 2026
Merged

fix(storage): clear obsolete onboarding intent#3571
Astro-Han merged 2 commits into
apache:mainfrom
mikemikimike:fix/obsolete-onboarding-intent

Conversation

@mikemikimike

Copy link
Copy Markdown
Contributor

Issue

Fixes#3566.

Background

A stale connection-onboarding journal can become permanently unreplayable when the catalog contains the same provider slug with a different connection ID. Every subsequent interactive runtime-policy store open then fails.

Changes

  • Treat the exact connection-id conflict as an obsolete onboarding intent.
  • Clear that intent and allow the store to open.
  • Preserve fail-closed recovery for all other errors.
  • Add a regression test covering reopen success and journal cleanup.

Compatibility

Only stale intents with the explicit identity conflict are discarded. I/O failures, malformed journals, vault failures, and other recovery errors retain their existing fail-closed behavior.

Verification

  • npm --workspace @maka/core run build — passed
  • npm --workspace @maka/storage run build — passed
  • node --test packages/storage/dist/__tests__/runtime-policy-stores.test.js — 47 passed, 6 skipped
  • npx biome check packages/storage/src/runtime-policy/coordinator.ts packages/storage/src/__tests__/runtime-policy-stores.test.ts — passed

Notes

The skipped tests require POSIX permissions or symlink support unavailable in the Windows environment. Full repository build/lint were not run because this change is scoped to the storage workspace and its focused checks were sufficient for the affected path.

Generated-by: Codex

@Astro-HanAstro-Han left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent review at exact head bdc1d702dc34b254748cbfac4a38dbd6a2cb0c86.

APPROVE. The recovery path is correct and the regression test is the right shape.

The fix closes a real dead end: a runtime-policy-onboarding.json whose connectionId no longer matches the catalog previously escaped as commit_outcome_unknown, and because the intent file was never cleared, every subsequent open hit the same wall. Clearing the obsolete intent and returning makes the state self-healing, and the test proves it across two successive reopens rather than just one — which is what distinguishes "recovered" from "recovered once".

The narrowing is also correctly ordered: the obsolete-intent branch is checked before isCommitOutcomeUnknown, so genuinely unknown commit outcomes still propagate untouched. No behaviour change for any other invalid_document failure.

[P3]packages/storage/src/runtime-policy/coordinator.ts:1399-1405 discriminates on free-text message equality:

error.code==='invalid_document'&&error.message==='Onboarding intent conflicts with the connection id'

invalid_document is raised from a dozen sites in connection-catalog-document.ts alone, so the message string is carrying the entire discrimination load for a control-flow decision that swallows an error. Rewording the throw at connection-catalog-document.ts:534 would silently restore the old dead end.

Mitigating this materially: the new test drives the real thrower end-to-end rather than constructing the error, so a reworded message does fail the suite. That is why this is [P3] and not higher — the coupling is covered, just implicitly. If you want it explicit, a dedicated error code (or an exported message constant shared by both sites) would make the contract local instead of spread across two files. Fine to leave as-is.

Verification: exact-head test is completed/success. The Dependency audit workflow does not appear on this head, which is correct rather than missing — it is path-filtered to package.json / lockfile / audit scripts, and this PR touches neither.

@Astro-Han
Astro-Han merged commit fe0ed22 into apache:mainAug 23, 2026
1 of 2 checks passed
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(storage): a non-convergent onboarding intent permanently bricks the runtime-policy store

2 participants

@mikemikimike@Astro-Han